Privacy Policy

Last updated: December 4, 2024

This Privacy Policy describes how HERS ELARA (the “Site,” “we,” “us” or “our”) collects, uses and discloses your personal information when you visit www.herselara.com (the “Site”), use our services, make a purchase or otherwise interact with us (collectively, the “Services”). In this Privacy Policy, “you” and “your” refer to you as a user of the Services, regardless of whether you are a customer, website visitor or other person whose information we have collected in accordance with this Privacy Policy.

Please read this Privacy Policy carefully. By using and accessing the Services, you consent to the collection, use and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access the Services.

SECTION 1 - CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time, including to reflect changes in our practices or for other operational, legal or regulatory reasons. We will post the revised Privacy Policy on the Site, update the “Last Updated” date, and take any other steps required by applicable law.

SECTION 2 - INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE RESPONSIBLE PERSON

(a) We are pleased that you are visiting our website and would like to thank you for your interest. Below we inform you about how we treat your personal data when you use our website. Personal data is any data that can be used to identify you personally.

(b) The data controller of this website within the meaning of the General Data Protection Regulation (GDPR) is HERS ELARA. The controller of the processing of personally identifiable data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

(c) This website uses cookies for security reasons and to facilitate the transmission of personal data and other confidential content (e.g. orders or requests to the controller) use SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the lock symbol in the line of your browser.

SECTION 3 - DATA COLLECTION WHEN VISITING OUR WEBSITE

If you use our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the data that your browser sends to our server (so-called “server log files”). When you visit our website, we collect the following data, which is technically necessary to display the website:

  1. the website you visited;
  2. date and time of access;
  3. the amount of data sent in bytes;
  4. source/reference from which you accessed the page Browser used;
  5. operating system used;
  6. IP address used (if applicable: in anonymized form).

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be transferred or used in any other way.

However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.

SECTION 4 - COOKIES

To make your visit to our website more attractive and to enable the use of certain functions, we use so-called cookies. These are small text files that are stored on your device. Some of the cookies used by us are deleted at the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your device and enable us or our partner companies (third-party cookies) to recognize your browser the next time you visit (persistent cookies). When cookies are set, certain user data are collected and processed individually, such as browser and location data and IP address values. Persistent cookies are automatically deleted after a certain period of time, which may differ for each cookie.

In some cases, cookies are used to simplify the ordering process (for example, by remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is also processed by individual cookies, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR for the performance of the contract or pursuant to Art. 6 para. 1 lit. f GDPR to ensure our legitimate interests in the best possible functionality of the website and a customer-friendly and effective organization of the website visit.

We may work with advertising partners who help us make our website more interesting to you. For this purpose, cookies from partner companies are also stored on your hard drive (third-party cookies). If we cooperate with the aforementioned advertising partners, the following paragraphs inform you separately and distinctly about the use of such cookies and the scope of information collected in each case.

Please note that you can set your browser to inform you about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies for certain cases or in general. Each browser is different in the way it manages cookie settings. This is described in each browser's help menu, which explains how to change your cookie settings. You can find these for the respective browsers at the following links:

  1. Microsoft Edge: https://support.microsoft.com/nl-nl/windows/cookies-beheren-in-microsoft-edge-weergeven-toestaan-blokkeren-verwijderen-en-gebruiken-168dab11-0753-043d-7c16-ede5947fc64d
  2. Firefox: https://support.mozilla.org/nl/kb/clear-cookies-and-site-data-firefox?
  3. Chrome: https://support.google.com/chrome/answer/95647?hl=en&hlrm=en
  4. Safari - Mac: https://support.apple.com/en-ca/guide/safari/sfri11471/mac
  5. Safari - Iphone: https://support.apple.com/en-us/105082
  6. Opera: https://help.opera.com/nl/latest/web-preferences/#cookies

If you do not accept cookies, the functionality of our website may be limited.

SECTION 5 - CONTACT

When you contact us (for example, via contact form or via e-mail), personal data is collected. The data collected in the case of a contact form are indicated in the respective contact form. This data is stored exclusively to respond to your request or for contact and related technical administration and use. The legal basis for processing the data is our legitimate interest to respond to your request in accordance with Art. 6 Para. 1 lit. f GDPR.

If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after your request has been processed, which is the case if circumstances indicate that the matter in question has been finally clarified and provided that there are no legal obligations to the contrary.

SECTION 6 - DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING

In accordance with Art. 6 Para. 1 lit. b GDPR, personal data will still be collected and processed if you provide us with this information to execute a contract or open a customer account. Which data is collected can be seen on the relevant input forms.

You can delete your customer account at any time by sending a message to the above address of the responsible party. We store and use the data you provide for processing the contract. After the contract has been fully processed or after you have deleted your customer account, your data will be blocked in accordance with tax and commercial law retention periods and deleted upon expiration of these periods, unless you have expressly consented to the further use of your data or if we have reserved the right to further use your data as permitted by law, about which we will inform you below.

SECTION 7 - USE OF YOUR DATA FOR DIRECT MARKETING

(a) Subscription to our email newsletter: If you subscribe to our e-mail newsletter, we will send you information about our offers on a regular basis. The only mandatory information for sending is your e-mail address. Providing further data is voluntary and is used to address you personally.

For sending the newsletter we use the so-called double opt-in procedure. This means that we only send you an e-mail newsletter if you have explicitly confirmed that you want to receive the newsletter. We then send you a confirmation e-mail in which we ask you to confirm that you want to receive the newsletter in the future by clicking on a corresponding link. want to receive the newsletter.

By activating the confirmation link, you authorize us to use your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. When registering for the newsletter, we store the IP address recorded by your Internet Service Provider (ISP) and the date and time of registration in order to trace any misuse of your e-mail address at a later date. The data we collect when you sign up for the newsletter is used exclusively to advertise in the newsletter.

You can unsubscribe from the newsletter at any time via the link in the newsletter or by sending a message to the responsible person mentioned at the beginning. After unsubscribing, your e-mail address will immediately be removed from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes. Uses of your data that are permitted by law and about which we inform you in this statement.

(b) Sending of email newsletter to existing customers: If you have provided us with your e-mail address when purchasing goods or services, we reserve the right to send similar goods or services to those already purchased from our range by e-mail. We do not require your separate consent for this. Data processing is carried out solely on the basis of our legitimate interest in personalized direct marketing in accordance with Art. 6 para. 1 lit. f GDPR.

If you have initially objected to the use of your e-mail address for this purpose, we will not send you e-mails. You have the right at any time to use your e-mail address for the above advertising purposes with effect for the future by sending a message to the responsible person, as the responsible person mentioned at the beginning. You only pay the transmission costs according to the basic rates. Upon receipt of your objection, the use of your e-mail address for advertising purposes will be stopped immediately.

SECTION 8 - DATA PROCESSING FOR ORDER PROCESSING

(a) The personal data collected by us will be passed on to the transport company that commissioned the delivery, to the extent necessary for the delivery of the goods. We will be passed on to the authorized credit institution for payment processing if this is necessary for the payment process. If payment service providers are used, we will explicitly inform you about this below. The legal basis for the transfer of data is Art. 6 para. 1 lit. b GDPR.

(b) Use of payment service providers:

Paypal

When paying via PayPal, credit card via PayPal, direct debit via PayPal or - if
offered - “purchase on account” or “instalment payment” via PayPal, we will pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). The data is transferred in accordance with Art. 6 Para. 1 lit. b GDPR and only to the extent that this is necessary for the payment process.

PayPal reserves the right to request a credit report via the payment methods credit card via PayPal, direct debit via PayPal or - if offered - “purchase on account” or “installment payment” via PayPal.

For this purpose, your payment data may be transmitted to credit bureaus in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of PayPal in determining your solvency to credit bureaus. PayPal uses the result of the credit check regarding the statistical probability of default, PayPal uses it to decide on the provision of the respective payment method.

The credit check may include probability values (called score values). To the extent that score values are included in the credit check result, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of score values includes, but is not limited to, address data. More information on data protection, including the credit reference agencies used, can be found in PayPal's data protection statement: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.

SOFORT

If you select the payment method “SOFORT,” the payment will be processed through the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter referred to as “SOFORT”), to whom we transfer the information about the ordering process along with the information about your order in accordance with Art. 6 Para. 1 lit. b GDPR. Sofort GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data will be transferred only for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose. You can find more information about SOFORT's data protection provisions: https://www.klarna.com/sofort/datenschutz

SECTION 9 - CONTACT US FOR A REVIEW REMINDER

We have our own review reminder (not sent by a customer review system). We use your email address to send you a one-time reminder to submit a review of your order to the review system we use, provided that you have given us express permission to do so during or after your order in accordance with Art. 6 para. 1 lit. a GDPR. You may withdraw your consent at any time by sending a message to the data controller.

SECTION 10 - USE OF SOCIAL MEDIA: SOCIAL PLUGINS

(a) Facebook plugins with Shariff solution: Special additional customs clearance fees and/or import duties are not included in the price and are the responsibility of the customer. Our website uses so-called social plugins (“plugins”) of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”).

To better protect your data when visiting our website, these buttons are not fully integrated as plugins, but are only integrated into the page via an HTML link. This type of integration ensures that when you visit a page on our website that contains such buttons, there is not yet a connection to the Facebook servers. When you click the button, a new browser window is opened and Facebook is called up, where (after entering your login data, if necessary) you can interact with the plugins there.

Facebook Inc. is based in the United States and is certified to the US-European Privacy Shield data protection agreement, which ensures compliance with the EU's data protection level.

The purpose and scope of data collection and further processing and use of data by Facebook, as well as your rights in this regard and setting options for protecting your privacy, please refer to Facebook's privacy policy: https://www.facebook.com/policy.php

(b) Google+ plugins as Shariff solution: Our website uses so-called social plugins (“plugins”) from the social network Google+, which is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
To better protect your data when you visit our website, these buttons are not fully integrated as plugins, but only through an HTML link. This type of integration ensures that when you visit a page on our website that contains such buttons, there is not yet a connection to the servers of Google+. When you click the button, a new browser window opens and loads the Google+ page Google+, where (after entering your login credentials, if necessary) you can interact with the plugins there. Google LLC, based in the United States, is certified under the US-European data protection agreement “Privacy Shield”, which guarantees compliance with the level of data protection applicable in the EU.

The purpose and scope of data collection and further processing and use of the data by Google, as well as your rights in this regard and setting options to protect your privacy, please refer to Google's data protection information: https://www.google.com/intl/nl/policies/privacy/.

(c) Instagram plugin as Shariff solution: Our website uses so-called social plugins (“plugins”) from the online service Instagram, which is operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”).

To better protect your data when you visit our website, these buttons are not fully integrated as plugins, but only through an HTML link. This type of integration ensures that when you visit a page on our website that contains such buttons, there is not yet a connection to Instagram's servers. When you click the button, a new browser window opens and calls up Instagram's, where (after entering your login credentials, if necessary) you can use plugins.

Instagram LLC, based in the US, is certified to the US-European Privacy Shield data protection agreement, which ensures compliance with the EU's data protection level.

The purpose and scope of data collection and further processing and use of data by Instagram, as well as your rights in this regard and settings options for protecting your privacy, can be found in Instagram's privacy policy: https://help.instagram.com/155833707900388/.

SECTION 11 - ONLINE MARKETING

(a) DoubleClick by Google: This website uses the online marketing tool DoubleClick by Google, which is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“DoubleClick”).

DoubleClick uses cookies to display ads relevant to users, to improve campaign performance reports or to prevent a user from seeing the same ads multiple times. Google uses a cookie ID to record which ads are displayed in which browser and can thus prevent them from being displayed multiple times. The processing is based on our legitimate interest to optimize the marketing of our website in accordance with Art. 6 Para. 1 lit. f GDPR.

In addition, DoubleClick may use cookie IDs to record so-called conversions related to ad requests. This is the case, for example, when a user sees a DoubleClick ad and later uses the same browser to visit the advertiser's website and purchases something there. According to Google, DoubleClick cookies do not contain any personal information.

Due to the marketing tools used, your browser automatically establishes a direct connection to Google's server. We have no influence on the scope and further use of the data that Google collects through the use of this tool Google and therefore we inform you based on our knowledge: Through the integration of DoubleClick, Google receives the information that you have visited the relevant part of our website or clicked on an advertisement. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or not logged in, the provider may find out and store your IP address.

If you wish to object to your participation in this tracking process, you can disable conversion tracking cookies by setting your browser to block cookies from the www.googleadservices.com domain, https://www.google.de/settings/ads, although this setting will be removed when you delete your cookies.

You can also learn more about the use of cookies from the Digital Advertising Alliance (at www.aboutads.info) to learn more about the use of cookies and make appropriate settings. Finally, you can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. If you choose not to accept cookies, the functionality of our website may be limited.

Google LLC, based in the United States, is certified for the US-European data protection agreement “Privacy Shield,” which ensures compliance with the level of data protection applicable in the EU.

You can find more information about the data protection provisions of DoubleClick by Google: https://www.google.nl/policies/privacy/.

(b) Use of Google AdWords Conversion Tracking: This website uses the online advertising program “Google AdWords” and, as part of Google AdWords, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

We use the Google Adwords to use advertising media (so-called Google Adwords) on external websites to draw attention to our attractive offers. We can determine how successful the individual advertising measures are in relation to the data from the advertising campaigns individual advertising measures are. In doing so, we pursue the interest of showing you what is of interest to you, to make our website more interesting for you and to achieve a fair calculation of advertising costs.

The conversion tracking cookie is set when a user clicks on an AdWords ad. Cookies are small text files stored on your computer system. These cookies are usually valid for 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was on that page.

Each Google AdWords customer receives a different cookie. This means that cookies cannot be tracked through AdWords customers' websites. The information collected using the conversion cookie is used to compile conversion statistics for AdWords customers who have chosen conversion tracking. Customers can see the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag.

However, they do not receive information that identifies users personally. If you do not want to participate in tracking, you can block this use by disabling the Google Conversion Tracking cookie through your Internet browser under user settings. You will then not be included in conversion tracking statistics. We use Google Adwords based on our legitimate interest in targeted advertising in accordance with Art. 6 para. 1 lit. f GDPR.

Google LLC, based in the US, is certified for the US-European data protection agreement “Privacy Shield,” which ensures compliance with the level of data protection applicable in the EU. You can find more information about Google's data protection provisions: https://www.google.nl/policies/privacy/.

You can permanently disable cookies for advertising preferences by preventing them using appropriate settings in your browser software or by downloading and installing the browser plug-in available at the following link: https://www.google.com/settings/ads/plugin?hl=nl.

Please note that certain features of this website may not work or may work only to a limited extent if you have disabled the use of cookies.

SECTION 12 - WEB ANALYTICS SERVICES

Google (Universal) Analytics: This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

Google Analytics uses so-called “cookies”, text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including the abbreviated IP address) is usually transmitted to a Google server in the USA and stored there. This website uses Google Analytics exclusively with the extension “_anonymizeIp()”, which ensures that the IP address is anonymized by abbreviation and prevents direct personal identification. The extension ensures that your IP address is anonymized by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be forwarded to a Google in the USA and truncated there. In these exceptional cases, this processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.

Google will use this information on our behalf to evaluate your use of the website, to compile reports on website activity and to provide us with further services relating to website and internet usage. The IP address transmitted from your browser will not be merged with other Google data.

You can prevent the storage of cookies by selecting the appropriate settings in your browser software; however, we point out that in this case you may not be able to fully use all the functions of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and prevent the processing of this data by Google by downloading and installing the browser plug-in via the following link: https://tools.google.com/dlpage/gaoptout?hl=nl.

Google LLC, based in the United States, is certified for the American-European data protection agreement “Privacy Shield”, which guarantees compliance with the data protection level.

This website also uses Google Analytics for cross-device analysis of visitor flow, which is performed via a user ID. When a page is a page, the user is assigned a unique, permanent and anonymized ID, which is set on different devices. This makes it possible to analyze interaction data from different devices and from different sessions of one user. The user ID contains no personal data and does not pass it on to Google. You can object to the collection and storage of data via the user ID with effect for the future at any time. To do so, you must disable Google Analytics on all systems you use, for example in another browser or on your mobile device. You can disable this with a browser plugin from Google: https://tools.google.com/dlpage/gaoptout?hl=nl.

More information about Universal Analytics can be found here: https://support.google.com/analytics/answer/2838718?hl=nl&ref_topic=6010376.

SECTION 13 - RETARGETING/ REMARKETING/ RECOMMENDED ADVERTISING

(a) Facebook Custom Audience via the pixel process: This website uses the “Facebook pixel” from Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). With your explicit consent, users' behavior can be tracked after they see or click on a Facebook ad. This procedure is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and may help to optimize future advertising measures. The data collected is anonymous to us, so we cannot draw any conclusions about the identity of users. However, the data is stored and processed so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, in accordance with Facebook's privacy policy: https://www.facebook.com/about/privacy/.

You may enable Facebook and its partners to serve ads on and outside Facebook. For these purposes, a cookie may also be stored on your computer. These processing operations are carried out only with your express consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent for the use of the Facebook pixel may only be given by users over 13 years of age. If you are younger, we ask you to ask your legal guardian for consent.

Facebook Inc. is gevestigd in de Verenigde Staten en is gecertificeerd voor de US-European Privacy Shield gegevensbeschermingsovereenkomst, die naleving van het EU gegevensbeschermingsniveau garandeert.

To disable the use of cookies on your computer, you can set your Internet browser to prevent cookies from being stored on your computer in the future or to delete all cookies already stored on your computer. However, disabling all cookies may mean that some features on our website can no longer function. You can also find the use of cookies by third parties, such as Facebook, at the following Digital Advertising Alliance website: https://www.aboutads.info/choices/.

(b) Google AdWords Remarketing: Our website uses the Google AdWords Remarketing feature, through which we advertise for this website in Google search results and on third-party websites. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). 

For this purpose, Google places a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. The processing is based on our legitimate interest to optimize the marketing of our website in accordance with Art. 6 para. 1 lit. f GDPR. Further data processing takes place only if you have allowed Google to link your Internet and app browsing history to your Google account and to use information from your Google account to personalize the advertisements you view on the Internet. If you are logged in to Google when you visit our website, Google uses your information along with Google Analytics data to create and define audience lists for cross-device remarketing. To do this, Google temporarily links your personal data with Google Analytics data to form target groups. You can permanently disable setting cookies for advertising preferences by downloading and installing: https://www.google.com/settings/ads/onweb/.

You can also learn more about the use of cookies and how to change your settings by visiting the Digital Advertising Alliance website (at www.aboutads.info). Finally, you can set your browser to inform you about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies for certain cases or in general. The functionality of our website may then be limited.

Google LLC, based in the United States, is certified for the American-European data protection agreement “Privacy Shield”, which guarantees compliance with the level of data protection. More information and the data protection provisions regarding advertising and Google can be found here: https://www.google.com/policies/technologies/ads/.

SECTION 14 - RIGHTS OF THE DATA SUBJECT

(a) The applicable data protection legislation grants you the following rights against the controller with respect to the processing of your personal data, extended data subject rights (right of access and intervention), which we will:

Right of access under Art. 15 GDPR:

In particular, you have the right to access about your personal data being processed by us, the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients to whom your data have been disclosed or the planned storage period or the criteria for determining the storage period, the existence of a right to rectification, erasure, restriction of processing, object to processing filing a complaint with a supervisory authority, the origin of your data if it has not been collected by us from you, the existence of automated decision-making including profiling and, if applicable, meaningful information on the logic involved and the scope and intended consequences of such processing for you, as well as your right to processing, as well as your right to be informed about the safeguards in accordance with Art. 46 GDPR when your data are transferred to third countries;

Right to rectification according to Art. 16 GDPR:

You have the right to rectification of incorrect data relating to you and/or completion of your incompletely stored data;

Right to erasure under Art. 17 GDPR:

You have the right to have your personal data erased if the conditions of Art. 17 para. 1 GDPR. However, this right does not apply if the processing is necessary for the exercise of the right to freedom of expression and information, the fulfillment of a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims;

Right to restriction of processing in accordance with Art. 18 GDPR:

You have the right to request the restriction of the processing of your personal data as long as the accuracy of your data is verified, if you refuse to have your data erased due to unauthorized data processing and instead request the restriction of the processing of your data, if you have data to assert, exercise or defend legal claims after we no longer need this data for the purpose for which it was collected or if you have objected on grounds related to your specific situation, as long as it has not yet been established whether our legitimate reasons outweigh yours;

Right to information in accordance with Art. 19 GDPR:

If you have the right to rectification, erasure or restriction of processing to the controller, the controller is obliged to inform all recipients to whom personal data about you have been disclosed of this rectification or erasure of data or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right to be informed of these recipients;

Right to data portability in accordance with Art. 20 GDPR:

You have the right to receive personal data you have provided to us in a structured, machine-readable format or to request that it be transferred to another data controller, insofar as this is technically feasible;

Right to withdraw consent in accordance with Art. 7 (3) GDPR:

You have the right to withdraw your consent to the processing of data at any time with effect for the future. In case of revocation, we will delete the relevant data immediately, provided that further processing cannot be based on a legal basis for processing without consent. By withdrawal of consent, the lawfulness of processing carried out on the basis of the consent to withdraw;

Right of appeal in accordance with Art. 77 GDPR:

If you believe that the processing of your personal data is in violation of the GDPR, you have the right to lodge a complaint with a supervisory authority, without prejudice to any other administrative or judicial remedy - the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or location of the alleged breach.

(b) Right to object

If we process your personal data based on our overriding legitimate interest, you have the right to object to such processing at any time, for reasons that arise, to object to such processing with effect for the future.

If you exercise your right to object, we will stop processing the data in question. However, we reserve the right if we can demonstrate compelling protective reasons for the processing that outweigh your interests, fundamental rights and freedoms, or if the processing serves to enforce, exercise or defend legal claims.

If your personal data is processed by us for direct marketing, you have the right to object to the processing of your personal data for the purpose of such advertising. You may exercise your right to object as described above.

If you exercise your right to object, we will stop processing the data in question for direct marketing purposes.

SECTION 15 - DURATION OF STORAGE OF PERSONAL DATA

The duration of storage of personal data is based on the respective legal retention period (e.g. commercial and tax retention periods). After the expiration of the retention period, the relevant data are routinely deleted, provided that they are no longer required for the performance of the contract or are necessary for the performance of the contract or the initiation of a contract and/or we do not have a legitimate interest to continue storing the data.

SECTION 16 - USER GENERATED CONTENT.

The Services allow you to post product reviews and other user-generated content. If you choose to submit user-generated content on a public area of the Services, that content is public and accessible to everyone.

We do not control who has access to the information you make available to others and cannot guarantee that parties who have access to such information will respect your privacy or keep such information secure. We are not responsible for the privacy or security of any information you disclose, or for the accuracy, use or misuse of any information you disclose or receive from third parties.

SECTION 17 - CONTACT INFO

If you have any questions about our privacy practices or this privacy policy, or if you wish to exercise any of the rights available to you, please e-mail info@herselara.com.